Arstechnica iconArstechnicaSep 22, 2026 ~4 min source read

Microsoft disrupts EvilTokens platform after 12,000 Microsoft account compromises

EvilTokens sold a subscription service that automated device-code phishing, inbox analysis, and fraud workflows to make large-scale email compromises and invoice fraud faster and easier.

Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

Share this story

Send the public story page.

Useful takeaways from this story.

EvilTokens used device code authentication phishing to enroll attacker devices and compromised about 12,000 Microsoft accounts at roughly 10,000 organizations.

The platform combined automated spam campaigns, backend automation, and an AI-style chatbot that analyzed inboxes to identify high-value targets and draft convincing fraud emails.

Organizations should treat a compromised inbox as immediately high risk and verify any payment or account-change requests through a separate trusted channel.

# What happened Microsoft led an operation that disrupted EvilTokens, a subscription-based criminal platform that compromised roughly 12,000 Microsoft accounts across about 10,000 organizations. The takedown seized 50 websites and 150 domains used to run the service, and the UK's Metropolitan Police Service arrested two men in connection with the platform.

# How EvilTokens worked EvilTokens automated most steps of a mass-compromise and post-compromise fraud workflow.

  • Delivery: The service automated large-scale spam campaigns that lured recipients to click malicious links or attachments.
  • Device-code phishing: Clicking the links led victims to webpages running hidden automation that interacted with Microsoft's identity provider in real time to generate a device code. Victims were instructed to copy that code into Microsoft's official device login portal, which enrolled an attacker-controlled device using the legitimate device code authentication flow.
  • Inbox analysis and targeting: An AI-style chatbot on the platform analyzed inbox contents at scale (up to 5,000 compromised emails at a time) to identify trusted relationships, payment authorizations, and employees who could disburse large amounts.
  • Fraud orchestration: The platform recommended fraud strategies and drafted believable follow-up messages that impersonated trusted contacts or managers to trick employees into transferring funds to attacker accounts.

Microsoft described the result as a shift in how quickly criminals can understand an inbox: what used to take days can now happen in minutes.

# Scope and victims Microsoft said the highest concentration of compromised accounts was in the United States, followed by Canada, the UK, Australia, India, and France. Affected sectors included wholesale distribution, construction, financial services, real estate, higher education, and healthcare.

# Technical details worth noting EvilTokens abused the legitimate OAuth device code authentication flow, which is intended for devices without standard input (for example, smart TVs). The malicious pages generated dynamic device codes and used automation on the backend (Node.js) to interact with identity providers in real time. That dynamic behavior helped the operation evade signature- and pattern-based detection.

# Response and partners Microsoft used legal authority and a partner network to seize infrastructure. SpyCloud assisted with victim details. Other organizations named in related coverage assisting the disruption included Cloudflare, Coinbase, OpenAI, Railway, The Shadowserver Foundation, TRM Labs, and Health-ISAC.

# Practical advice for organizations Assume that a compromised inbox can be fully understood and weaponized quickly. Concrete steps cited by Microsoft and implied by the incident:

  • Apply strong identity protections such as multi-factor authentication that resists device-code phishing flows and monitor device enrollments closely.
  • Independently verify any request to change payment details, redirect funds, or approve unusual transactions using a second trusted channel (for example, a known phone number or in-person confirmation).
  • Monitor for unusual OAuth device enrollments and implement logging and alerts for high-risk account activity.

# Why this matters EvilTokens packaged and automated tasks that previously required manual effort: mass delivery, device-code phishing, inbox parsing, target selection, and message drafting. That packaging reduced the time and skill needed to scale financial fraud and invoice scams across many organizations.

More context around this story.

AI бЂ”бЂЉбЂєбЂёбЂ•бЂЉбЂ¬бЂЂбЂ­бЂЇ бЂЎбЂ™бЂјбЂ”бЂєбЂ†бЂЇбЂ¶бЂё бЂњбЂ±бЂ·бЂњбЂ¬бЂ”бЂЉбЂєбЂё
Medium iconMediumSep 5, 2026

AI бЂ”бЂЉбЂєбЂёбЂ•бЂЉбЂ¬бЂЂбЂ­бЂЇ бЂЎбЂ™бЂјбЂ”бЂєбЂ†бЂЇбЂ¶бЂё бЂњбЂ±бЂ·бЂњбЂ¬бЂ”бЂЉбЂєбЂё

AI (Artificial Intelligence) နည်းပညာက အá€á€¯á€¡á€á€»á€­á€”်မှာ နေရာá€á€­á€¯á€„်းမှာ ရှိနေပါပြီዠဒါပေမဲ့ “AI ကို ဘယ်ကနေ စလေ့လာရမလဲአအမြန်ဆုံး á€á€á€ºá€™á€¼á€±á€¬á€€á€ºá€¡á€±á€¬á€„်â

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app